2、互联,共配置3个子接口,DLCI分别是100 200 300(两端相同)。二、测试结论:未做任何策略#interface Ethernet0/0 ip address 192.168.1.1 255.255.255.0=在路由器A Tracert路由结果如下:dis clock08:48:03 UTC Fri 11/28/2008tracert -m 5 -a 192.168.1.2 192.168.2.2 traceroute to 192.168.2.2(192.168.2.2) 5
3、 hops max,40 bytes packet Press CTRL_C to break 1 192.168.1.1 3 ms 1 ms 2 ms 2 10.0.0.10 19 ms 18 ms 19 ms 3 192.168.2.2 20 ms 21 ms 20 ms由此可得出未做route-policy的时候,是按照全局路由表中的路由条目转发数据流的。1、permit+permit#interface Ethernet0/0 ip address 192.168.1.1 255.255.255.0 i
4、p policy route-policy t1#acl number 3000 rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255acl number 3001 rule 0 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255#route-policy t1 permit node 10 if-match acl 3000 app
5、ly ip-address next-hop 10.0.0.2route-policy t1 permit node 20 apply ip-address next-hop 10.0.0.6在路由器A Tracert路由结果如下:dis clock 08:50:33 UTC Fri 11/28/2008tracert -m 5 -a 192.168.1.2 192.168.2.2 traceroute to 192.168.2.
6、2(192.168.2.2) 5 hops max,40 bytes packet Press CTRL_C to break 1 192.168.1.1 2 ms 2 ms 1 ms 2 10.0.0.2 20 ms 20 ms 22 ms 3 192.168.2.2 19 ms 20 ms 19 ms由此结果可得出此时数据流匹配了规则node 10 。也就是route-policy permit对于和ACL permit规则匹配的数据流执行node 10中的匹配规则。2、permit+deny#interfa
7、ce Ethernet0/0 ip address 192.168.1.1 255.255.255.0 ip policy route-policy t2#acl number 3000 rule 0 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255acl number 3001 rule 0 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255